Amazon MQ broker inventory

Record the purpose and owner of each message broker.

Description

An Amazon MQ broker inventory documents messaging assets and the services using them. A broker’s presence alone does not indicate a vulnerability.

Potential impact

Unlisted brokers may be missed in access-control and logging reviews, and their owners may be harder to locate during an outage.

Remediation

Record the owning team and connected services, then check network access, authentication, logging, and engine support.

Examples

These excerpts add tags. Supply a supported ActiveMQ version and a separately managed strong password through the variables. Tags alone do not complete the broker’s security configuration.

Before

hcl
resource "aws_mq_broker" "broker" {
  broker_name         = "app-broker"
  engine_type         = "ActiveMQ"
  engine_version      = var.activemq_engine_version
  host_instance_type  = "mq.t3.micro"

  user {
    username = "appuser"
    password = var.broker_password
  }
}

After

hcl
resource "aws_mq_broker" "broker" {
  broker_name        = "app-broker"
  engine_type        = "ActiveMQ"
  engine_version     = var.activemq_engine_version
  host_instance_type = "mq.t3.micro"

  tags = {
    Service     = "messaging"
    Environment = "production"
  }

  user {
    username = "appuser"
    password = var.broker_password
  }
}

References